CVE-2026-81383
- EPSS 0.71%
- Veröffentlicht 08.09.2026 17:18:51
- Zuletzt bearbeitet 10.09.2026 14:48:34
Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
CVE-2026-78462
- EPSS 0.52%
- Veröffentlicht 08.09.2026 17:18:29
- Zuletzt bearbeitet 11.09.2026 21:11:03
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-81381
- EPSS 0.62%
- Veröffentlicht 08.09.2026 17:14:00
- Zuletzt bearbeitet 15.09.2026 13:31:41
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
CVE-2026-81380
- EPSS 0.63%
- Veröffentlicht 08.09.2026 17:13:59
- Zuletzt bearbeitet 23.09.2026 19:51:23
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
CVE-2026-81379
- EPSS 0.33%
- Veröffentlicht 08.09.2026 17:13:59
- Zuletzt bearbeitet 11.09.2026 21:08:42
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-81378
- EPSS 0.33%
- Veröffentlicht 08.09.2026 17:13:58
- Zuletzt bearbeitet 11.09.2026 21:09:03
Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-81377
- EPSS 0.77%
- Veröffentlicht 08.09.2026 17:13:58
- Zuletzt bearbeitet 11.09.2026 21:09:23
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
CVE-2026-81376
- EPSS 0.66%
- Veröffentlicht 08.09.2026 17:13:57
- Zuletzt bearbeitet 11.09.2026 21:09:45
Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-81357
- EPSS 0.29%
- Veröffentlicht 08.09.2026 17:13:56
- Zuletzt bearbeitet 11.09.2026 21:10:10
Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-81356
- EPSS 0.33%
- Veröffentlicht 08.09.2026 17:13:56
- Zuletzt bearbeitet 11.09.2026 21:10:38
Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.